C)SA1 logo
Focused certification exam prep
Start practice

What Is C)SA1 Certification?

TL;DR
  • C)SA1 is Mile2's Certified Security Awareness 1, aimed at end users, employees and managers, not security specialists.
  • Mile2's public outline lists eight unweighted preparation topics, from Mile2 introduction through incident response and security culture.
  • Question count, timer and passing score are unverified for C)SA1; do not borrow figures from other Mile2 exams.
  • No prerequisites exist, and Mile2 training is not mandatory, though the class is a two-hour live session.

What Certified Security Awareness 1 Actually Is

Certified Security Awareness 1 is an entry-level credential from the Mile2 Cybersecurity Institute. It is built for people whose job is not security but whose daily behavior determines how secure their organization is: the employee opening email, the manager sharing files, the contractor logging into a portal. The certification verifies that a person understands the human-side risks behind most breaches and knows how to respond to them.

Because several unrelated credentials abbreviate to similar letters, a quick scope note helps. This article covers only the standalone Mile2 Certified Security Awareness 1 certification. It does not describe a combined C)SA1/C)SA2 course, and it does not describe any other organization's exam that happens to share the acronym. If you want a quick orientation on the name itself, the short explainers on what C)SA1 stands for and the meaning of C)SA1 cover the terminology.

Course completion is not certification: Finishing the Mile2 awareness class and earning the Mile2 certification are two different things. The certification is awarded through the exam process in your Mile2 account. When an employer asks whether you are "certified," that means the credential, not a class attendance record.

Who Issues It and Who It Targets

Mile2 is a cybersecurity training and certification provider, and the first topic in its C)SA1 outline is literally an introduction to who Mile2 is. That framing tells you something about the product: it is an awareness program with a certification attached, designed to be approachable rather than deeply technical.

The intended audience is broad:

  • End users who handle email, files and accounts every day.
  • Employees across departments such as HR, finance, operations and sales.
  • Managers who set the tone for security behavior on their teams.

There is no expectation of networking knowledge, scripting ability or prior IT experience. That distinguishes it from technical security certifications, and it is why it fits organizations that want a documented baseline of awareness across the whole workforce. For the formal eligibility picture, see our breakdown of C)SA1 requirements and prerequisites.

The Eight Preparation Topics

Mile2's public three-page course outline organizes preparation into an introduction plus seven numbered modules (00 through 06). We present these as eight preparation topics. They are unweighted: Mile2 has not published a percentage blueprint, so no topic can honestly be called "the biggest" or "most tested." Treat all eight as fair game, and note that the outline is a preparation guide, not a guarantee of exhaustive exam coverage. For a deeper walkthrough, our complete guide to the C)SA1 content areas goes topic by topic.

Domain 1: INTRODUCTION: Who is Mile2?

The orientation material about the issuing organization and what its credentials represent.

  • Know who issues the certification and why awareness training exists
  • Understand the context for the rest of the course

Domain 2: 2025 Cyberthreat Trends

An overview of the threat landscape facing ordinary users and organizations.

  • Recognize the categories of attack that target people rather than systems
  • Understand why attackers favor everyday workers as an entry point
  • Note: the "2025" in the heading is a course title, not an exam version designation

Domain 3: The Human Factor

Why human behavior is central to security outcomes.

  • Understand how habits, stress, urgency and trust get exploited
  • Connect individual choices to organizational risk

Domain 4: Phishing & Social Engineering

Recognizing and resisting manipulation attempts across channels.

  • Spot suspicious emails, messages, calls and links
  • Understand pretexting, impersonation and pressure tactics
  • Know the correct action when something looks wrong

Domain 5: Credentials, Passwords, and Access Security

Protecting the keys to accounts and systems.

  • Understand password hygiene and the risks of reuse
  • Know why multi-factor authentication matters
  • Recognize how access should be limited and handled responsibly

Domain 6: Data Protection & Handling Sensitive Information

Treating information according to its sensitivity.

  • Distinguish sensitive from routine information
  • Understand safe storage, sharing and disposal behavior

Domain 7: Communication Security & Collaboration Tools

Staying safe in email, messaging and shared workspaces.

  • Recognize risks in chat, file sharing and collaboration platforms
  • Apply sensible habits when communicating about sensitive matters

Domain 8: Incident Response, Security Culture, and Wrap-Up

What to do when something goes wrong, and how culture prevents it.

  • Know that prompt reporting beats quiet embarrassment
  • Understand the employee's role in an incident
  • See how a supportive culture reduces risk

Notice the arc: it starts with context and threats, moves to the human element, then spends the middle on practical defensive behaviors, and finishes with response and culture. That progression is a useful mental map when you review.

Exam Format: What Is and Isn't Confirmed

This is the area where honesty matters most. Mile2's public documentation does not give a verified question count, item format, exact timer or passing threshold for C)SA1 that we can responsibly state. Here is why those numbers are unsettled:

  • The exam-information paragraph in the course PDF names a different Mile2 course, Certified Network Principles, so its passing-score statement is not treated as C)SA1 policy.
  • Mile2's Policies and Procedures document (dated 5-26-2026, page 17) states a general rule of 100 multiple-choice items for its exams, but expressly excludes C)SA1 and C)SA2 from that rule.
  • The two-hour live class and the four CEUs attached to it describe training, not the exam timer.
Do not import numbers from other exams: If a site tells you C)SA1 has exactly 100 questions or a specific passing percentage, treat that with suspicion. Mile2's own policy carves C)SA1 out of the 100-item rule. For what we can and cannot say, see our pages on the passing score and on how hard the exam is.

Likewise, we do not publish a candidate pass rate, because none has been verified. Our pass rate discussion explains what can and cannot be concluded from public information.

How the Exam Is Delivered and Supervised

Delivery is online through your Mile2 account and its learning management system. There is no test-center trip. Where sources diverge is supervision:

Mile2 SourceWhat It Describes
Frequently Asked QuestionsMost standard exams are on-demand, with no live-proctor appointment required
Policies and Procedures, page 18Proctored, open-book assessment with advance scheduling

These two descriptions do not obviously align, and neither is specific to C)SA1. The practical advice is simple: before you begin, confirm in your Mile2 account exactly what supervision applies to your assigned exam and which resources you may use. Do not assume open-book rules, and do not assume you can start at any hour without checking. Scheduling specifics are covered in our exam dates and scheduling guide.

The Exam Combo, Attempts and Pricing Caveats

Mile2 sells the certification as the C)SA1 Exam Combo. The public inclusion list names three items:

  • The certification exam
  • An exam simulator
  • A prep guide

Mile2's FAQ and exam-combos page indicate two attempts per Exam Combo, which gives you a retake cushion but also means you should not treat the first sitting as a free trial.

A pricing caution: Earlier reviews we examined recorded an advertised bundle price of USD 150, with one also recording USD 495 as an original price. No price appeared in the product text retrieved for this article, so we cannot present either as a verified current checkout price, and we have no verified standalone-voucher fee. Check the live Mile2 product page before budgeting. Our cost breakdown lays out what to verify.

We also did not review the paid prep guide's contents or the live exam itself. What we describe about the exam comes from public outlines, products and policies, not from sitting it.

Prerequisites and Training Options

There are no suggested prerequisites. Mile2 training is not mandatory, so you can attempt the certification without taking the class. That said, the live class exists and is worth understanding:

  • It runs about two hours, in English, live.
  • It carries four CEUs.
  • Those figures describe the class, not the exam.

If you prefer structured instruction, the class is a convenient on-ramp; if you are a self-directed reader, the outline plus the combo's prep guide and simulator may be enough. Our overview of C)SA1 training options compares the paths.

Validity and Renewal

The certification is valid for three years. Mile2's renewal materials describe the standard route this way:

  • Document 60 CEUs over the three-year period.
  • Purchase the renewal.
  • Acknowledge the ethics and policy statement.

The dedicated "Paths to Renewal" page also lists an alternative: passing the latest exam for your existing credential. Mile2's FAQ gives a USD 200 U.S. regional price for CEU renewal and states there is no annual membership requirement.

Conflicting renewal statements: The course PDF presents a current exam and 20 annual CEUs as joint requirements, and policy page 22 couples annual CEUs with an exam-or-renewal-purchase requirement. That differs from the dedicated alternative-path page. These should not all be read as simultaneously binding. Confirm which route and deadline apply to you directly with Mile2 rather than assuming.

Workplace Value and Who Benefits

An awareness credential rarely functions as a standalone job qualification. Its value tends to be organizational and supporting: it documents that an employee has been assessed on safe behavior, which can help teams demonstrate baseline training to auditors, insurers or customers who ask. Individuals may find it a credible first line on a resume, particularly for roles that touch sensitive data, or as a stepping stone toward more technical study.

We make no promise of a pay increase, and we do not cite salary figures for this credential, because none have been verified. If you want to weigh the decision, our worth-it analysis, the salary guide and the page on C)SA1-related jobs discuss it without inventing numbers.

Sequencing Your Preparation Around the Eight Topics

Since the topics are unweighted, a sensible plan is to give every topic a pass and spend extra time where your daily habits are weakest. One short, topic-tied schedule:

Week 1

Foundations and Threats

  • Cover Mile2's introduction, 2025 Cyberthreat Trends and The Human Factor
  • Goal: be able to explain why people are the primary target
Week 2

Attack Recognition and Access

  • Work through Phishing & Social Engineering, then Credentials, Passwords, and Access Security
  • Rehearse what you would actually do when you see a suspicious message
Week 3

Data, Communication, Response

  • Cover Data Protection, Communication Security & Collaboration Tools, and Incident Response and Security Culture
  • Finish with a full review and practice questions on all eight topics

For a fuller approach, see our C)SA1 study guide and the one-page cheat sheet. You can also test yourself on original questions at the C)SA1 practice test site; our items are written from scratch around the eight topics rather than reproducing any exam content.

Key Takeaway

Scenario thinking beats memorization here. Most awareness questions reward knowing the safest sensible action, such as reporting a suspicious email instead of deleting it quietly, so practice choosing responses, not reciting definitions.

Frequently Asked Questions

Who issues the C)SA1 certification?

The Mile2 Cybersecurity Institute issues Certified Security Awareness 1. It is a standalone certification, distinct from any other organization's exam that shares a similar abbreviation.

Do I need experience or prerequisites?

No. There are no suggested prerequisites, and Mile2 training is not mandatory. The course is intended for end users, employees and managers.

How many questions are on the exam and what is the passing score?

These details are unverified for C)SA1. Mile2's policy document excludes C)SA1 from its general 100-item rule, and the course PDF's passing statement refers to a different course. Confirm in your Mile2 account.

How long is the certification valid?

Three years. Renewal typically involves documenting 60 CEUs, purchasing renewal and acknowledging ethics policy, though the alternative of passing the latest exam is also published. Confirm your applicable route with Mile2.

Is the exam proctored and can I use resources?

Mile2's sources conflict: the FAQ describes most exams as on-demand without a live proctor, while a policy page describes proctored, open-book assessment with advance scheduling. Verify the rules for your assigned exam before starting.

Ready to pass your C)SA1 exam?

Put this into practice with free C)SA1 questions across every exam domain.